IT Services
Contract
Netherlands
The Hague
Needed
NCIA
Essential Qualifications/Experience:
· Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience. Exceptionally, the lack of a university degree may be compensated by the demonstration of 10 years particular abilities or experience of interest to NCIA
· A professional Qualification CIS Security e.g. CompTIA Security+/ CISM/ ISC2 - CISSP, and/or equivalent certification
· Risk Management certification or equivalent
· Knowledge of NATO or national processes for ATO
· Experience with PILAR or (RMF) risk management framework. Knowledge of common IT security frameworks and governance models
· Knowledge of NATO responsibilities and organization to include NATO Security Policy and supporting directives.
· Knowledge of NATO responsibilities and organization, including ACO
DUTIES/ROLE:
· Oversight and support to Information Security and NATO CIS Security Accreditation activities. This includes provision of relevant expertise, direct support to specific projects and the conduct of security risk assessments
· Project Support: security design, CIS Security Risk Assessment, security requirements, security testing and validation, interoperability and security operating procedures
· Information security: advise on security aspects to manage identified risks and ensure adoption and adherence to standards for complex ISR information systems. Develop security architectures that mitigate the risks
· Information assurance: Interpret and apply information assurance and security policies to manage risks. Plan and conduct information assurance and security accreditation of complex cross-functional domains and areas, cross-functional areas
· Risk management: Plan and implement complex security risk management activities within a specific function, technical area, project or programme. Implement consistent and reliable security risk management processes and reporting to key stakeholders
· Vulnerability assessment/ Penetration Testing: Plan and manage vulnerability assessment and/or penetration testing activities
All the mandatory requirements have to be met in order to apply.